
Last updated: July 6, 2026
This page describes Prava's security approach for Prava Pay, Prava Wallet, Prava SDK, Prava APIs, Prava dashboards, Prava websites, and embedded Prava payment flows.
1. Security model
Prava is a technology service provider for agentic commerce. Prava helps users and authorized agents create payment permissions, authenticate approvals, tokenize card credentials, apply spend controls, and route approved payment instructions. Payment processing, authorization, clearing, settlement, money movement, issuing, acquiring, refunds, and chargebacks are handled by card networks, including Visa, Mastercard, and other supported networks where applicable, banks, PSPs, processors, money transmission partners, merchants, and other regulated or licensed parties.
2. Card-network and partner requirements
Prava supports Visa Intelligent Commerce where available and operates payment flows subject to applicable card-network, partner, security, consent, and compliance requirements.
3. PCI and vaulting
Prava maintains current PCI DSS Level 2 / SAQ-D compliance for its applicable platform and services. Prava uses Skyflow, a PCI DSS Level 1 vault provider, for card vaulting. Card data is collected through secure payment and vaulting flows. Prava does not store raw card numbers or CVV in its application databases. Prava conducts vulnerability scanning, security review, and compliance review as part of its PCI program.
4. Tokenization and spend controls
Prava uses tokenization and scoped payment credentials designed to limit payment use by approved merchant, amount, expiry, use count, mandate, or other approved controls. AI agents and apps do not receive the user's underlying card number or CVV. In approved workflows, they may receive scoped payment credentials for checkout.
5. Authentication and consent
Prava uses passkeys and other authentication controls to help verify user approval before issuing or enabling payment credentials. One-time payments require user approval. Mandates require user approval before activation and operate only within approved limits. Before a proposed transaction proceeds, Prava or the integrated experience must present applicable payment details and obtain sufficient user authority to proceed.
6. Restricted merchant controls
Prava may block or restrict agentic payments involving restricted or high-risk merchant categories, including adult content, escort services, gambling, prescription-only drugs, tobacco, weapons, cryptocurrency, wallet funding, P2P transfer, financial trading, negative-option billing, outbound telemarketing, public file-sharing services, or other restricted categories. These controls may be enforced by Prava, card networks, issuers, PSPs, processors, merchants, or other payment partners.
7. Technical safeguards
Prava uses safeguards designed to protect systems and data, including encryption in transit; encryption or equivalent protection at rest where applicable; least-privilege access controls; access logging and monitoring; secure credential handling; environment separation; vulnerability scanning and security testing as part of the PCI program; and vendor and partner controls where applicable.
8. Developer and user responsibilities
Users and developers must protect devices, accounts, passkeys, API keys, webhook secrets, and agent access. Developers must not log, store, expose, or misuse card credentials, payment tokens, PAN, CVV, or other sensitive payment data except as expressly permitted by Prava. Users and developers must review merchant, amount, mandate, and checkout details before approval or execution.
9. Incident response
Prava reviews suspected security incidents and takes action based on severity, legal obligations, partner obligations, and user impact. Where required, Prava will notify affected users, customers, partners, regulators, or other parties.
10. Vulnerability reporting
Report security issues to support@prava.space. Do not publicly disclose a vulnerability until Prava has had a reasonable opportunity to investigate and address it. Prava does not offer a bug bounty unless agreed in writing.
11. Limitations
Security controls reduce risk but do not eliminate it. Prava does not guarantee that any system, partner, agent, merchant, browser automation, or checkout flow will be uninterrupted, error-free, or completely secure.
